Apache Superset up to and including 1.0.1 allowed for the creation of an external URL that could be malicious. By not checking user input for open redirects the URL shortener functionality would allow for a malicious user to create a short URL for a dashboard that could convince the user to click the link.
Metrics
Affected Vendors & Products
References
History
Tue, 24 Feb 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Apache Superset Open Redirect | Apache Superset Open Redirect |
Status: PUBLISHED
Assigner: apache
Published: 2021-04-27T09:27:22.000Z
Updated: 2024-08-03T21:33:17.571Z
Reserved: 2021-03-10T00:00:00.000Z
Link: CVE-2021-28125
No data.
Status : Modified
Published: 2021-04-27T10:15:09.693
Modified: 2024-11-21T05:59:07.970
Link: CVE-2021-28125
No data.